Operational trust readiness - UAT/demo disclosure
Security and vulnerability disclosure
Billie security contact, vulnerability disclosure expectations, safe harbor language, and current platform posture for product readiness review.
Report a vulnerability
Email security@kenac.co.zw with a concise description, affected route, reproduction steps, impact, and your preferred contact. Do not include passwords, PINs, full card numbers, or unnecessary identity documents.
Testing scope
Good-faith testing may cover public Billie web pages, documented API routes, webhook verification, authentication boundaries, and tenant isolation signals. Do not access customer data, disrupt service, or run destructive tests.
Security posture
Billie uses deny-by-default authorization patterns, HttpOnly session storage, parameterized backend access, structured audit evidence, secret references for sensitive values, and encrypted transport. This page does not claim SOC 2, ISO 27001, PCI DSS, or regulator certification.
Safe harbor
Billie will not pursue action for good-faith research that avoids privacy harm, data destruction, extortion, persistence, public disclosure before remediation, or service disruption. Reports may be limited by legal, banking, or regulator obligations.
Security and privacy requests are routed separately. Use the data-subject request route for access, correction, deletion, restriction, objection, or portability requests.
Submit a data-subject request